Your site has been compromised (hacked). There are tons of posts and articles on how to de-hack a site. It can be done, but is very time-consuming.
At very least, update/reinstall everything (WordPress, Themes, plugins), change passwords for database and all admin users, remove any unknown admin users, look for extra php files (in every single folder on your site).
You might try the free WordFence plugin to scan your site and look for hacked files (delete them).
Assume that you’ll spend at least 20 hours in fixing/removing things.
Related Posts:
- What’s the effect if this malware if infected your WP?
- Malware on site [closed]
- How to find the backdoor of the hack
- My wordpress site was hacked – is my htaccess file compromised?
- My WordPress Blog sends malicious traffic to other sites [closed]
- Hacked WordPress website, as notified by Google Search Console, what to do? [closed]
- How was my WP site hacked [closed]
- If a WP install is hacked, can it spread to other domains on a server?
- Find and Replace text in the entire table using a MySQL query
- Is it a good idea to rename the “index.php” in “wp-admin” folder to avoid being hacked?
- How to fight this wp-info.php exploit? [closed]
- Prevent Hacking of WordPress Site [closed]
- Suspicious URLs being loaded after hack and restore
- Server hacked: correct contents of wp-uploads directory? [closed]
- Site hacked with malware [closed]
- Copy wordpress website pages and content
- How do I know if my WP Theme is using infamous TimThumb?
- Spam pages hack? [closed]
- Check for malicious code?
- Why would a hacker add this code to each post, and how to do mass cleanup?
- Is the current spate of hacks related to the recent security fix?
- I have removed the malware from our website however, when I tried again to search the word from Google it is still there [closed]
- Have I been hacked? Mysterious code at the top of theme files [closed]
- Strange codes in my wordpress site and my website is running too slow [closed]
- Spam Content Serving from old cached version of site?
- How to solve wordpress redirection (no malware was found)?
- Help determining if the following are legitimate files
- My blog was hacked? WP posting random posts
- Have I been hacked – getting new site setup email for 8 localhost wordpress sites
- Site Hacked – WordPress Divi Site – Cannot find where to fix the issue? [closed]
- malware in wordpress installer on dreamhost. [closed]
- Where I can find a list of WordPress security risks?
- looking for indoxploit hack solution [closed]
- Why functions.php file automatically empty?
- Bruteforce attack from 127.0.0.1?
- WordPress installer attack
- Why wordpress is hitting another url
- Where do hackers usually run their hacking script? [closed]
- Malicious Code in Index.php WordPress [closed]
- WP Site Hacked, Serp Google Spam [closed]
- My site appears to be hacked [closed]
- WordPress Redirect Hack
- Strings of malicious code to look for after a hack
- Hacked/cloaked sitemap [closed]
- Not able to change WordPress admin email. Someone added another admin credentials
- WordPress site hacked. Has .htaccess been hacked?
- Tips for finding SPAM links injected into the_content
- Scanning Database for malicious Data
- What should I do about hacked server?
- How can I find security hole in my wordpress site?
- Has anyone experience w/ WordPress (MultiSite) hidden users (possibly hacked)?
- Hacked website redirect, only on desktop, help with restoring it [closed]
- How do i disable/disallow and tags in TinyMCE?
- Change WP-Login or WP-Admin
- Security issues with WP sites
- How to prevent wp-login brute force attack from thousand of different IP? [duplicate]
- How To Clean The Malware Infected & Hacked WordPress Websites? [duplicate]
- Increased CPU load due to admin-ajax.php spam
- getting casino links on my woocommerce site [closed]
- How to locate & delete hidden pages on a site
- Verifying that I have fully removed a WordPress hack?
- How can I safely hide the fact that my website runs on WordPress? [closed]
- WordPress Footer Missing After Website Hack
- My WordPress Websites are always under attack
- Spam users registers even when registration is disabled
- What does this code do? (Injected code hacked)
- My WordPress website was hacked [closed]
- Some one is trying to hack my website, Need guidance [closed]
- Efficient way to check local WordPress php files and Database for malicious code? [duplicate]
- What can I do when an outside party hacks into my weblog and changes my display name?
- Any known bugs that could cause disappearance of the wp_users table?
- Is there any pre-existing plugin to track and block IPs with suspicious activity on my site?
- On new server, site got hacked, permissions a bit strange? Please help
- Website show Google Ads when we have no Google Ads linked to our website
- Multiple attempted logins originating from the server IP itself?
- Is there a simple way to set wordpress site files back to out of the box?
- Remove hacked code – out of ideas! [closed]
- Username was changed to “admin”
- Site blocked by WebSense on fresh WP Install
- WordPress disable direct access of files in WordPress installation path
- Am receiving more than thousand mails in single day from ‘[email protected]’ continuously
- Is this a hack? WordPress Usernames of every website we have changed into one single name automatically?
- How to bulk delete a certain part of all wordpress posts
- Should I prevent access to .htaccess and wp-config.php files?
- WordPress Database Re-installed (Hacked)
- How to log into WordPress via GET/POST
- Verifying that I have fully removed a WordPress hack?
- Subpage is redirecting to spam site
- how can i find malware code and remove from wordpress site to stop it redirecting to hackers click view pages
- Open content directory help!
- Replacing nav-menus.php file with standard clean one?
- Hacked site using transient API?
- After being hacked Fatal error: Call to undefined function get_header() in 404.php on line 1
- Could a user account with a stolen password compromised entire WP site?
- how to find the way they hacked my WP site
- How to stop repeated hack on header.php of custom theme? [closed]
- My WordPress site hacked with unwanted popups [closed]
- Redirected You too Many Times and Homepage Not Loading
- WordPress website is redirecting on some different shopping page
- WordPress broken dashboard with ninja-shell text